PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94544 vercel CVE debrief

CVE-2026-94544 debrief: Next.js vulnerability allows Draft Mode content leakage through shared pending `use cache` fills, impacting sites with Cache Components or experimental.useCache enabled. This occurs when Draft Mode requests and regular requests overlap, causing the second request to receive the first request's fill. As a result, a regular request may receive unpublished content without authentication, while a Draft Mode request may receive published content instead of the draft. If the overlapping regular request prerenders a page, the unpublished content can be persisted into the generated page and served to later visitors until the page is revalidated. The vulnerability is

Vendor
vercel
Product
next
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and administrators of sites using Next.js with Cache Components or experimental.useCache and serving Draft Mode previews should assess exposure and verify content leakage. This includes reviewing Draft Mode usage, verifying persisted pages for potential unpublished content, and considering upgrades to mitigate the vulnerability. Security teams and operators should prioritize verifying exposure and assessing the impact on their environments.

Why it matters

CVE-2026-94544 allows leakage of Draft Mode content into regular responses and persisted pages in Next.js, impacting sites with Cache Components or experimental.useCache enabled

  • Unpublished content can be served to regular users without authentication
  • Draft Mode requests may receive published content instead of draft content
  • Persisted pages can be generated with unpublished content and served to later visitors
  • Verification of exposure and content leakage is necessary

Technical summary

Pending `use cache` fills in Next.js can leak Draft Mode content into regular responses and persisted pages when overlapping requests occur. This happens because cached functions are shared across requests without distinguishing between Draft Mode and regular requests. As a result, a regular request may receive unpublished content, while a Draft Mode request may receive published content. The vulnerability can lead to persisted pages being generated with unpublished content and served to later visitors until the page is revalidated.

Defensive priority

Defenders should prioritize verifying exposure and assessing Draft Mode usage

Recommended defensive actions

  • Verify if Cache Components or experimental.useCache is enabled and serving Draft Mode previews
  • Assess exposure of Draft Mode usage and content
  • Consider upgrading to version 16.3.8 or later
  • Review and revalidate persisted pages for potential unpublished content
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence from the source corpus indicates that sites using Next.js with Cache Components or experimental.useCache and serving Draft Mode previews are affected. The source item detailing the vulnerability confirms that overlapping requests can lead to content leakage. To verify exposure, defenders should assess Draft Mode usage and content. The official CVE Program record and NIST NVD detail page provide additional context on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94544 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94544

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94544 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94544

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.